Cubbie Conference December 10, 2026 in San Francisco Get tickets →

Free, open-source web application security scanner maintained by OWASP for finding vulnerabilities in web applications during development and testing.

Pricing

Free

Founded

2010

Team size

1-10 employees

Headquarters

Open Source

Product Preview

OWASP ZAP preview

Preview from zaproxy.org

At a glance

Best for

Security Engineer

Pricing model

Free

Try before you buy

About OWASP ZAP

OWASP ZAP is a free, open-source web application security scanner used for finding vulnerabilities in web apps and APIs. It targets security testers and developers doing dynamic application security testing (DAST), both manually and in CI/CD. Capabilities include an intercepting proxy, automated active and passive scanning, fuzzing, scripting, and an API for automation, maintained as an OWASP flagship project.

Buyer Fit & Positioning

Procurement & Fit

Structured facts from the vendor to help your security, finance, and procurement reviews move faster.

Trust

Security & compliance

The vendor hasn’t added security or compliance details yet.

Pricing

Commercial model

Pricing model: Free

Free trial: No

Free plan: Yes

Contract minimum: Not specified

Procurement

Purchasing & legal

The vendor hasn’t added purchasing & legal details yet.

Fit

Best-fit company size

Company-size fit has not been specified yet.

Implementation & Procurement

Commercial Fit & Ecosystem

Proof, Outcomes & Momentum

Alternatives, Migration & Buyer Objections